Overview
Once your data is flowing and your teams are remediating, the next question leadership always asks is: “Are we actually getting better?” The Executive Metrics page is where you answer that. It gives security leaders, managers, and team leads a single, side-by-side view of a broad set of best-practice vulnerability management metrics, whether you manage risk by Asset Group, by Assigned Team, or by individual Assignee. Use it to build comparisons for board reporting, governance meetings, quarterly security reviews, or weekly ops check-ins, without spreadsheets, manual pulls, or stale exports. This article provides an overview on using the Executive Metrics page and a reference section describing each of the available metrics.
Why this matters
Ingesting, prioritizing, and remediating only matter if you can measure the outcome and communicate it to the people who fund the program. The Executive Metrics page allows you to prove the progress of your program and analyze insights into where things might be creating bottlenecks
Accountability at a glance. Compare team against team, business unit against business unit, or crown-jewel assets against everything else, using the same yardstick for all of them.
Better risk conversations. Move leadership past raw “critical” counts toward SLA adherence, aging, and threat-informed exposure.
Zero-effort reporting. The numbers are always live, so a saved view shows you where things stand today.
Tip
The quality of your comparisons depends on the structure behind whichever lens you pick. Asset group comparisons are only as good as your Projects & Asset Group structure, and team or assignee comparisons are only as good as your assignment data. Review both before you report on the numbers.
Getting Started
Select Metrics under Analyze in the left menu. You’ll land on the default view: performance metrics for All Assets.
.png)
Building a comparison takes four steps: choose your Group By lens, select the groups, teams, or people you want to compare, pick the metrics that matter, then arrange the table and (optionally) save the whole combination as a reusable view.
Choosing a Group By Lens
Executive Metrics can present the same metric library through three different lenses. Use the Group By toggle at the top of the selection panel to switch between:
Asset Groups: compare groups of assets, for example by business unit, environment, or region (the default). Best for infrastructure- and business-unit-level risk posture, or answering where the risk lives.
Assigned Team: compare the teams findings are assigned to. Best for cross-team accountability and workload reporting, or answering who owns the work and how each team is tracking against SLAs.
Assignee: compare the individual users findings are assigned to. Best for understanding how remediation workload is distributed within a team and for grounding 1:1s and workload conversations in real numbers.
Assigned Team and Assignee use the same metric library, and the metric definitions and calculation rules are identical no matter which lens you choose. Only the rows being compared change, along with the label on the frozen first column.
The extra lenses matter because most security programs don’t assign work purely by asset ownership. Multiple teams often own different finding types on the same asset, such as a network team handling OS-level findings while an application team handles library vulnerabilities on that same server. Grouping by asset group alone hides who is accountable for the work. Grouping by Assigned Team or Assignee lets you report on past due rates, MTTR, and churn directly, without forcing everything back into an asset lens.
.png)
.png)
Hit the Apply button at the bottom of the Row Selector (Select Teams, Groups, etc)
Selecting Asset Groups
Use the Select Asset Groups panel to choose one or more asset groups to compare, then click Apply.
Each selected (checked) group becomes its own row in the Performance Metrics table on the right.
Use the Search box to filter the list. Type a string and press Enter to narrow long lists of asset groups.
How to Use
The rows are your peers under comparison. Selecting “Cloud – Prod,” “Cloud – Dev,” and “Corp IT” side by side shows you right away which team is outrunning its SLAs and which one is falling behind.
Selecting Assigned Teams
Switch the dimension to Assigned Teams to compare metrics for the teams that vulnerability instances are assigned to. Choose one or more teams in the Select Teams panel, then click Apply.
Each selected (checked) team becomes its own row in the Performance Metrics table, and the frozen first column becomes Assigned Team.
Use the Search box to filter the list. Type a string and press Enter to narrow long team lists.
The teams shown reflect the assigned team value on your vulnerability instances, so the list mirrors how work is being routed today.
How to Use
Asset groups tell you where the exposure sits. Assigned teams tell you who is accountable for closing it. This is the fastest way to answer “which teams are meeting their SLAs?” without rebuilding your asset group structure to match your org chart, which helps when one team remediates across many groups or several teams share the same group.
Selecting Assignees
Switch the dimension to Assignee to break the same metrics down by the individual each instance is assigned to. Choose one or more assignees in the Select Assignees panel, then click Apply.
Each selected (checked) assignee becomes its own row, and the frozen first column becomes Assignee.
Assignee lists are usually the longest of the three dimensions, so use the Search box and press Enter to find people quickly.
Select a handful of assignees at a time. A focused set of rows is much easier to read, and to act on, than every assignee in the environment at once.
How to Use
Team-level numbers can hide uneven distribution inside the team. Grouping by assignee shows how remediation work is spread across owners: where the queue is backing up, who is carrying an outsized share of past-due items, and where a reassignment or extra capacity would help most. It gives 1:1s and workload conversations a factual starting point. Read it as a workload and routing view, since the numbers reflect what was assigned and when.
Selecting Custom Fields
Switch the dimension to Custom Field to break the same metrics down by any of the custom fields you set up in your environment. Choose one or more fields in the Select Values panel, then click Apply.
Each selected (checked) field: Values combination becomes its own row, and the frozen first column becomes the custom field you are grouping by.
.png)
How to Use
The power of custom fields is that you can group any vulnerability instance together based on your arbitrary logic. This means that your metrics report can now be based on any criteria you deem important to your organization. We recommend utilizing a few common patterns, such as:
Campaign - grouping by a campaign allows you to see how your remediation efforts are going on a precise set of findings you are targeting to resolve.
Reachability and Exposure Management: Custom fields allow you to compare resolution, SLA adherence, and other core metrics across any finding dimension, such as exposure management focused groupings. One such example is reachable findings vs non-reachable findings.
Remediation Queue: You can add findings to a remediation queue and only ticket on those queues. This allows you to compare metrics across different backlogs and queues as you see fit.
Selecting Metrics
Several common metrics are selected by default when opening the Executive Metrics page. To customize which metrics are displayed in the Performance Metrics table:
Click the Select Metrics button:
.png)
This will open a modal for you to select from the entire library of metrics
.png)
At the top are quick links to Clear Selections or Reset to Default selections.
After selecting which metrics to display, along with sub-options like severities to include and/or prior timeframe, click the Save button to apply your changes.
Working with the Performance Metrics Table
Selected Metrics appear as columns in the Performance Metrics table. The following capabilities allow you to further analyze and compare metrics across asset groups:
Sort by a given metric by single clicking the center area of column headers
Resize columns by dragging the right edge of the column header:
Reorder columns by dragging the center area of column headers
Freeze Columns:
The Asset Group column is Frozen by default, allowing you scroll horizontally through many metrics without losing context of which asset groups you are comparing
You can freeze additional columns by dragging them into the left of the freeze columns:
.png)
Saving Views
Saved Views store your Group By lens, your row selections, your metric selections, and your sorting and column order together, so you can rebuild specific, repeatable use cases in one click. For example:
Comparing team performance against SLA metrics for a weekly ops review.
Comparing risk and threat-intelligence metrics across asset categories for a leadership readout.
Comparing assigned teams or assignees against past-due and aging metrics for a workload and capacity check-in.
Saved Views provide the ability to save different combinations of asset group and metrics selections for specific use cases like comparing team performance against SLA metrics or comparing risk and threat intelligence metrics across asset categories.
To save a view:
After making the modifications you wish to save (asset group selections, metrics selections, sorting, column order, etc.), click the Save View button in the header of the Performance Metrics table:
.png)
Enter a unique View Name (required), optionally you can provide a description for the view, then click Save:
.png)
Your saved view is now available for quick access in the future under the Saved Views dropdown:
.png)
To modify a Saved View:
Open the Saved View you wish to modify.
Make desired changes such as asset group selections, metric selections, etc.
Click the dropdown arrow next to Save View, then select Save Changes:
.png)
To modify the Name and Description of a Saved View:
Click the view selector dropdown, then click the Edit button next to the Save View you wish to update:
Update the Name and/or Description, then click Save:
To delete a Saved View:
Click the view selector dropdown, then click the Delete button next to the Save View you wish to delete:
.png)
When prompted, click Delete to confirm deletion of the saved view, or click Cancel to return.
Metrics Reference
The following table provides a reference for available metrics along with a description for how each is calculated.
Key Things to Know
Instance-level metrics: All metrics on this page are calculated at the instance level → asset-vulnerability combination counts separately. For example, if CVE-2024-1234 exists on 10 servers, it counts as 10 instances.
Active assets only: Metrics are calculated on active assets only; inactive assets are excluded.
Informational severity excluded: Unless otherwise specified, vulnerabilities with a severity of Informational are not included.
Asset Group-only metrics: Risk Score, Asset Count, and Compliance metrics only appear when Group By is set to Asset Group. Switching to Assigned Team or Assignee hides these columns.
Unassigned findings are excluded from Assigned Team and Assignee lenses. Only findings with an assignment are counted, so totals under these lenses will be lower than under Asset Group for the same project.
Metrics Library
Category | Metric | Description |
|---|---|---|
Vulnerabilities | Active Vulnerabilities by Severity | Count of active vulnerability instances by severity. |
Vulnerabilities | Active Vulnerabilities by Status | Count of active vulnerability instances by status (Active, Exception Requested, In Progress, etc.) |
Vulnerabilities | Average Age of Active Vulnerabilities by Severity | Average number of days from Discovered Date until today for active vulnerability instances by severity. |
Vulnerabilities | Discovered in Last {#} Days by Severity | Count of vulnerability instances with a Discovered Date within the last {#} days by severity. This metric uses the finding's original discovery date. |
Vulnerabilities | Resolved in Last {#} Days by Severity | Count of vulnerability instances remediated in the last {#} days by severity. |
Vulnerabilities | % Churn in the Last {#} Days by Severity | Ratio of discovered vs. resolved vulnerability instances in the last {#} days by severity. This provides the ability to track whether or not your remediation velocity is keeping pace with rate at which new vulnerabilities are being discovered. How to interpret:
|
SLAs & Remediation | % Past Due Vulnerabilities by Severity | Percent of active vulnerability instances past their due date by severity. |
SLAs & Remediation | Past Due Vulnerabilities by Severity | Count of active vulnerability instances with due dates in the past by severity. |
SLAs & Remediation | % Active Within SLA by Severity | Percent of active vulnerability instances not past their due date. |
SLAs & Remediation | % Resolved Past SLA in Last {#} Days by Severity | Percent of vulnerability instances resolved past their due date for the last {#} days by severity. |
SLAs & Remediation | Resolved Past SLA in Last {#} Days by Severity | Count of vulnerability instances resolved past their due date for last {#} days by severity. |
SLAs & Remediation | % Resolved Within SLA in Last {#} Days by Severity | Percent of vulnerability instances resolved on or before their due date for the last {#} days by severity. |
SLAs & Remediation | Resolved Within SLA in Last {#} Days by Severity | Count of vulnerability instances resolved on or before their due date for last {#} days by severity. |
SLAs & Remediation | Active Vulnerabilities with no SLA by Severity | Count of active vulnerability instances without a set due date by severity. |
SLAs & Remediation | MTTR for Vulnerabilities Resolved in Last {#} Days by Severity | Average number of days from Discovered Date to Remediated Date for vulnerability instances resolved in the last {#} days by severity. |
SLAs & Remediation | Resolved in Last {#} Days by Status | Number of vulnerability instances resolved as {Status} in the last {#} days. |
Risk & Threat Intelligence | Risk Score | Nucleus Risk Score for the asset group. |
Risk & Threat Intelligence | Nucleus Threat Rating | Count of active vulnerability instances by Nucleus Threat Rating (Existential, Critical, High, Medium, Low). |
Risk & Threat Intelligence | Nucleus Zero Day by Severity | Count of active zero-day vulnerability instances based on Nucleus Insights threat intelligence data by severity. |
Risk & Threat Intelligence | Nucleus Known Exploited by Severity | Count of active vulnerability instances known to be actively exploited based on Nucleus Insights threat intelligence data by severity. |
Risk & Threat Intelligence | Nucleus Widely Exploited by Severity | Count of active vulnerability instances known to be widely exploited based on Nucleus Insights threat intelligence data by severity. |
Risk & Threat Intelligence | Nucleus Exploited by Malware by Severity | Count of active vulnerability instances with known malware exploits based on Nucleus Insights threat intelligence data by severity. |
Risk & Threat Intelligence | Nucleus Exploit Available by Severity | Count of active vulnerability instances with a publicly available exploit based on Nucleus Insights threat intelligence data by severity. |
Risk & Threat Intelligence | Nucleus Impacts OT by Severity | Count of active vulnerability instances that impact operational technology (OT) based on Nucleus Insights threat intelligence data by severity. |
Risk & Threat Intelligence | Nucleus Likely to be Exploited by Severity | Count of active vulnerability instances predicted to be exploited based on Nucleus Insights threat intelligence data by severity. |
Compliance | Compliance Pass % | Percent of compliance finding instances with a result of Passed or Warning. |
Compliance | Compliance Passes | Number of active compliance finding instances with a result of Passed or Warning. |
Assets | Number of Assets | Count of active assets in an asset group. |
Ticketing | Open Tickets | Count of open tickets created in external ticketing systems. |
Ticketing | Tickets Created in the Last {#} Days | Count of external tickets created in the last {#} days. |
Ticketing | Tickets Closed in the Last {#} Days | Count of external tickets closed in the last {#} days. |
Ticketing | % Past Due Vulnerabilities Without Tickets by Severity | Percent of active vulnerability instances past due without tickets created by severity. |
Ticketing | % Vulnerabilities Without Tickets by Severity | Percent of active vulnerability instances without tickets created by severity. |
Executive Metrics vs. Trends Page
You may notice differences between counts on the Executive Metrics page and similar metrics on the Trends page. This is by design—each serves a different purpose:
Executive Metrics | Trends Page | |
|---|---|---|
Counting method | Instance-level only | Unique and Instance views available |
Asset scope | Active assets only | All assets (including inactive) |
Discovered counts | Based on original discovery date | Includes rediscoveries |
Executive Metrics is optimized for point-in-time program measurement across asset groups. Trends is optimized for operational visibility over time.
Need a hand? We’re happy to help. Email [email protected].